- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
12-17-2025 02:48 PM
I have 4 portals and 4 gateways (4 different PA fw/vm ) of a GlobalProtect. PA is integrated with azure (an azure app per each gateway).
I added one more new portal and one more new subnet to the one of the existing gateways, a new dns a-record and a new azure app.
ISSUE: Clients can't connect to this portal, it's getting stuck after connection attempt. There're "success" events on the azure log and PA log. Also, I get "Authentication Failed" error by using azure app from myapps.microsoft.com
12-17-2025 05:04 PM
Hi @V.Tolstorozhikh ,
This sounds less like a GP settings misconfiguration and more like a SAML configuration issue to me. That said, I’d still start by verifying that the new portal is referencing the correct SAML IdP Server Profile tied to the new Azure app you configured.
When you mention seeing successful connection attempts, I’m assuming that’s based on the system logs. If so, is the GlobalProtect client actually getting stuck after the login redirect without presenting an explicit error or failure?
You also mentioned seeing “Authentication Failed” when launching the app from myapps.microsoft.com. In most cases, that behavior points back to the Azure enterprise app itself rather than GlobalProtect.
From the symptoms, it looks like the client is successfully redirecting to Entra ID for authentication (which would explain the “success” events), but the flow is breaking when Entra attempts to send the SAML response back to the portal, or the portal is rejecting the assertion.
In that case, I’d double-check that the ACS and Entity ID configured on the Azure app exactly match what the portal is expecting (including things like :443 if applicable), as even small mismatches there can cause this behavior.
As a final sanity check, I’d re-export and re-import the metadata, then open the XML and confirm the EntityID, ACS/Reply URL, and signing certificate all match what the portal expects.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

